From: Paul Barker <paul@pbarker.dev>
To: docs@lists.yoctoproject.org
Cc: Paul Barker <paul@pbarker.dev>
Subject: [PATCH v2 2/3] security-team: Tidy and update section on security team operations
Date: Wed, 03 Jun 2026 20:45:18 +0100 [thread overview]
Message-ID: <20260603-sec-team-v2-2-ee7d2016fbf4@pbarker.dev> (raw)
In-Reply-To: <20260603-sec-team-v2-0-ee7d2016fbf4@pbarker.dev>
The section "What Yocto Security Team does when it receives a security
vulnerability" duplicated information already found in the previous
section "Security Team Operations", so merge the sections and tidy up
the flow of the text.
While we're editing this, Mitre is now just one of the places you can go
to get a CVE assigned, many other CVE Numbering Authorities (CNAs) are
available. They also now have a web form for contact and requesting CVE
assignment so let's link directly to that.
Also drop "If an upstream project does not respond quickly" down a
heading level.
Signed-off-by: Paul Barker <paul@pbarker.dev>
---
documentation/security-reference/security-team.rst | 26 +++++++---------------
1 file changed, 8 insertions(+), 18 deletions(-)
diff --git a/documentation/security-reference/security-team.rst b/documentation/security-reference/security-team.rst
index 7ec1dda02e0c..c83ada17eb56 100644
--- a/documentation/security-reference/security-team.rst
+++ b/documentation/security-reference/security-team.rst
@@ -56,31 +56,21 @@ original reporter in the loop. There is also sometimes some coordination for
handling patches, backporting patches etc, or just understanding the problem
or what caused it.
-When the fix is publicly available, the YP security team member or the
-package maintainer sends patches against the YP code base, following usual
-procedures, including public code review.
-
-What Yocto Security Team does when it receives a security vulnerability
-=======================================================================
-
-The YP Security Team team performs a quick analysis and would usually report
-the flaw to the upstream project. Normally the upstream project analyzes the
-problem. If they deem it a real security problem in their software, they
-develop and release a fix following their own security policy. They may want
-to include the original reporter in the loop. There is also sometimes some
-coordination for handling patches, backporting patches etc, or just
-understanding the problem or what caused it.
-
The security policy of the upstream project might include a notification to
Linux distributions or other important downstream projects in advance to
discuss coordinated disclosure. These mailing lists are normally non-public.
When the upstream project releases a version with the fix, they are responsible
-for contacting `Mitre <https://www.cve.org/>`__ to get a CVE number assigned and
-the CVE record published.
+for contacting an appropriate CVE Numbering Authority (CNA), such as `Mitre
+<https://cveform.mitre.org/>`__, to get a CVE number assigned and the CVE
+record published.
+
+When the fix is publicly available, the YP security team member or the
+package maintainer sends patches against the YP code base, following usual
+procedures, including public code review.
If an upstream project does not respond quickly
-===============================================
+-----------------------------------------------
If an upstream project does not fix the problem in a reasonable time,
the Yocto's Security Team will contact other interested parties (usually
--
2.43.0
next prev parent reply other threads:[~2026-06-03 19:45 UTC|newest]
Thread overview: 7+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-06-03 19:45 [PATCH v2 0/3] Security team documentation updates Paul Barker
2026-06-03 19:45 ` [PATCH v2 1/3] security-team: Update membership list Paul Barker
2026-06-03 19:45 ` Paul Barker [this message]
2026-06-04 5:33 ` [docs] [PATCH v2 2/3] security-team: Tidy and update section on security team operations Marta Rybczynska
2026-06-04 8:22 ` Paul Barker
2026-06-03 19:45 ` [PATCH v2 3/3] security-team: Add section on multi-project embargoes Paul Barker
2026-06-09 7:27 ` [PATCH v2 0/3] Security team documentation updates Antonin Godard
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260603-sec-team-v2-2-ee7d2016fbf4@pbarker.dev \
--to=paul@pbarker.dev \
--cc=docs@lists.yoctoproject.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox